Florida Yet to Spend $30M Allocated for Cybersecurity

Florida Yet to Spend $30M Allocated for Cybersecurity

Lawmakers in Florida are asking why the state has failed to spend millions of dollars it was assigned to fund the implementation of new cybersecurity measures.

The Miami Herald reports that despite lawmakers’ allocating $30m for the improvements months ago, the Sunshine State is yet to spend a single cent.

The office of Florida’s statewide chief information officer, Jamie Grant, requested the money seven months ago with the understanding that it would be used for threat assessments, new software, and infrastructure hardening.

While $672,000 was to be spent on training, $3.2m was to be used to fund a new Cybersecurity Operations Center.

Quizzed by lawmakers on Wednesday over his office’s fiscal inaction, Grant gave the response that his office was too short-staffed to draw up a spending plan. He later declined to say when a plan would be put in place when questioned by the Herald.

In August, it was reported that Florida’s year-old IT agency – the Florida Digital Service – was struggling to keep key positions filled. 

Grant, a former state representative appointed to his leadership role in 2020 by Governor Ron DeSantis, said last month that personnel changes taking place in the Florida Digital Service were “consistent” with his team’s “shared principles.”

Since taking over, Grant has seen two chief information security officers, the chief data officer, the enterprise architect, the chief operations officer, and half of the state’s new ten-member cybersecurity team leave their jobs.

According to the Herald, several of the individuals quit suddenly without giving notice, with some telling the news source that they found Grant’s management style antagonistic. 

The high number of unfilled roles within the agency has attracted criticism. James Taylor, CEO of the Florida Technology Council, described the vacant positions on the cybersecurity advisory board as “a massive concern.”

Visitors to the Florida Digital Service website are told: “We need your help. Join the team.” The site does not contain a list of vacancies, but instead features an ‘apply now’ button that takes visitors to a contact form that they can use to state their skills or certifications and the policy area(s) in which they are interested. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Complex New SMS Malware Discovered

Complex New SMS Malware Discovered

Cell phone users in Canada and the United States are being targeted by a new and advanced form of SMS malware that lures victims with COVID-19-related content.

Threat analysts at Cloudmark discovered the new low-volume campaign attacking Android mobile device users and named it TangleBot. This complex malware can directly obtain personal information, control device interaction with apps and overlay screens, and steal account information from financial activities initiated on the device.

TangleBot sends SMS text messages themed around coronavirus regulations and third doses of COVID vaccines known as booster shots to entice users into downloading malware. Victims who take the lure unwittingly download malware that compromises the security of their device and configures the system so that confidential information can be exfiltrated to systems controlled by the attacker(s). 

The malware allows the threat actor(s) to control everything from call logs and contacts to the phone camera and GPS on an infected device and employs multiple levels of obfuscation to keep its presence hidden from the device’s user.

“The malware has been given the moniker TangleBot because of its many levels of obfuscation and control over a myriad of entangled device functions, including contacts, SMS and phone capabilities, call logs, internet access, and camera and microphone,” wrote the analysts. 

The messages sent as part of the malware campaign appear to be warnings or appointment notifications. One such SMS contained the text “New regulations about COVID-19 in your region. Read here:” followed by a malicious link.

Another preceded a malicious link with the statement: “You have received the appointment for the 3rd dose. For more information visit:”

Users who click on the link are taken to a website where they are notified that the Adobe Flash Player software on their device is out of date and must be updated for them to proceed. If the user clicks on the subsequent dialog boxes, TangleBot malware is installed on the Android device.

“As we have seen with FluBot, TangleBot can overlay banking or financial apps and directly steal the victim’s account credentials,” noted the analysts.

“Also, TangleBot can use the victim’s device to message other mobile devices, spreading throughout the mobile network.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

‘Anonymous’ Hackers Claim to Hit Website Hosting Firm Popular With Far-Right Groups

‘Anonymous’ Hackers Claim to Hit Website Hosting Firm Popular With Far-Right Groups

Last week, hacking group Anonymous claimed to have stolen and leaked data held by Epik, a website hosting firm popular with far-right organizations like the Proud Boys.

The reams of data, amounting to 150 gigabytes, include information about those who tried to overturn the 2020 presidential election. Epik has historically provided web hosting services to a number of conspiracy theorists and conservative media networks.

On Epik’s clientele list were several sites banned from other platforms for violating hate speech and misinformation policies. These include those associated with the Proud Boys, 8chan, Parler, and QAnon conspiracy groups. 

“On September 15, we confirmed that certain customer-account information for our domain-related systems was accessed and downloaded by unauthorized third parties,” tweeted the company, which calls itself the “Swiss Bank of Domains” on its website.

In a statement, Anonymous said they’ve stolen “a decade’s worth” of company data, including passwords, internal emails and clients’ home addresses and phone numbers.

The breach undermines Epik’s longstanding pledge that customer data would remain anonymous irrespective of views customers might share online. 

Megan Squire, a professor at Elon University who studies right-wing extremism, told The Washington Post that: “It’s massive. It may be the biggest domain-style leak I’ve seen and, as an extremism researcher, it’s certainly the most interesting. 

“It’s an embarrassment of riches — stress on the embarrassment.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Cybersecurity Vulnerability Could Affect Millions of Hikvision Cameras

Cybersecurity Vulnerability Could Affect Millions of Hikvision Cameras

On Sunday, video surveillance giant Hikvision posted a security advisory on its website warning customers of a cyber vulnerability that could impact millions of cameras and NVRs deployed globally. 

The “command injection vulnerability” could allow threat actors to have complete control of compromised devices and was discovered by cybersecurity researcher Watchful IP in June and first reported on Monday by IPVM

According to the security advisory, the vulnerability received a base score of 9.8 out of 10 per the Common Vulnerability Scoring System (CVSS), which Watchful IP called “the highest level of critical vulnerability.”

Although the video surveillance giant has not disclosed how many products are likely impacted, posting only product names and firmware versions, IPVM estimates that more than 100 million devices could be affected. 

In a letter to its partners, Hikvision informed integrators to download an updated version of firmware on its website to remediate the vulnerability.  

It also said: “We recognize that many of our partners may have installed Hikvision equipment that is affected by this vulnerability, and we strongly encourage  you to work with your customers to ensure proper cyber hygiene and install the updated firmware.”

Hikvision also said that it worked with Watchful IP to patch the vulnerability. Additionally, the company has patched all vulnerabilities reported to the company in its latest firmware version.

“Hikvision is a CVE Numbering Authority (CNA) and has committed to continuing to work with third-party white-hat hackers and security researchers, to find, patch, disclose and release updates to products in a timely manner that is commensurate with our CVE CNA partner companies’ vulnerability management teams,” the letter adds.

“Hikvision strictly complies with the applicable laws and regulations in all countries and regions where we operate and our efforts to ensure the security of our products go beyond what is mandated.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Cyber Threats Result in 60% Increase in Cyber Intelligence Sharing Among Financial Firms

Cyber Threats Result in 60% Increase in Cyber Intelligence Sharing Among Financial Firms

FS-ISAC (The Financial Services Information Sharing and Analysis Center) has announced that global cyber intelligence sharing among its member financial firms has soared by 60% from August 2020 to August 2021, caused by supply chain and ransomware threats. 

Record-breaking levels of intelligence sharing across all regions occurred due to large-scale threats. These areas included North America; Latin America; Europe, the UK, the Middle East, Africa and Asia Pacific.

Commenting on the news, FS-ISAC said that attacks against the financial sector and its supply chain have become a risk management imperative. Steven Silberstein, CEO of FS-ISAC, raised this point, saying that “With the increase in sophisticated cross-border cyber-criminal campaigns against the financial sector and its supply chain, sector-wide global collaboration has become a risk management imperative.

“Intelligence and best practice sharing across our community and platforms have reached new heights, spurred by the high-profile events of the last 12 months. We commend the members who go above and beyond to protect the financial system at large,” he added. 

Also commenting on this finding and stressing the importance of sharing intelligence, Fred Gibbins, chief information security officer at American Express, said: “American Express is deeply interconnected with the other players in the global financial system. We believe it is our critical responsibility to share intelligence and best practices with our peers to help the industry to protect and defend against emerging cyber threats. We are honored to be recognized by FS-ISAC and appreciate the collaboration between all the members for our collective protection.

“In Latin America, we benefit from intelligence that is shared by global US and Europe-based firms as well as from our neighboring countries,” said Juan Carrasco, head of cybersecurity at Banco Falabella Chile. “By monitoring attacks in Argentina and Brazil, we were able to predict and thwart a cyber-attack in Chile. This attests to the power of cross-border intelligence sharing in mitigating cyber risk,” he continued. 

Corsin Camichel, cyber threat intelligence regional lead at UBS, pointed out the importance of following information-sharing best practices: 

“As a global firm, UBS monitors the global cybersecurity landscape to proactively detect and mitigate risks. 

“Sharing intelligence and best practices with our peers and regional counterparts is fundamental to staying ahead of emerging cyber threats,” he said. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains